Executive brief
GiveWP is a popular WordPress plugin used by organizations to accept donations and manage fundraising campaigns. A security vulnerability has been identified that could allow an attacker to trick a site administrator into performing unintended actions, such as changing settings or deleting data, by clicking a malicious link. This could lead to unauthorized configuration changes or disruption of donation services.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the GiveWP plugin for WordPress in versions up to and including 4.16.3. The flaw is due to missing or insufficient nonce validation on certain administrative or state-changing functions. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator to visit a specially crafted webpage or click a malicious link. Successful exploitation allows the attacker to execute unauthorized actions with the privileges of the victim, potentially modifying plugin settings or donation records. The issue is resolved in version 4.16.4.
Affected products
- Nexcess / StellarWP GiveWP <= 4.16.3
Timeline
- 2026-07-02: other: Reported by researcher jh_hack
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date